πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 138 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bc3bc6e8-aae7-451e-b26a-cc5e8fcd0a33
< 2.3.10
HIGH 8.8 The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. wordfence
bc17284e-65ea-4e67-aba9-3475f0174657 HIGH 8.8 The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is… wordfence
bc0983d7-6c7e-41cb-8997-578d362d9c9f
< 3.6.4
HIGH 8.8 Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes … wordfence
bbf9a765-3718-4957-aa18-562654824fbf
< 1.5.8
HIGH 8.8 The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the… wordfence
bbd8dc5f-7a62-4258-a13e-e5cec911fdc4
< 3.0.0
HIGH 8.8 The Events Calendar for Google plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
bbc91abd-d865-45a2-bc37-f34cb10f1863
< 3.1.3
HIGH 8.8 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. wordfence
bbc00c4b-c360-4614-b9bc-30d899b812f1
< 1.9.5
HIGH 8.8 The WP Last Modified Info plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi… wordfence
bbae9c33-becb-4c9d-917f-0d8fe8312d0c
< 2.37
HIGH 8.8 The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… wordfence
bb65d916-7d9e-4562-ab9b-c7ba012a08fb
< 1.3.5
HIGH 8.8 The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead… wordfence
bb5e6767-d0a9-4ac4-816f-6fb57b1e5f9b
< 2.8.9
HIGH 8.8 The Uncode Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.8.8. This… wordfence
bb3be09d-6f65-48cc-b692-f4231d3f6858 HIGH 8.8 The SermonAudio Widgets plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.3 due … wordfence
bb3aa613-8f34-4d96-8ddf-41fcdcf65c59
< 12.3.20
HIGH 8.8 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ param… wordfence
bb267bbd-cd62-49f7-9abc-c6734b23be22
< 1.9.13
HIGH 8.8 The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va… wordfence
bb0e77e1-7e9f-4f7e-8953-c86ab0e5ae7a
< 6.8
HIGH 8.8 The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including… wordfence
bae06fa8-546c-4daf-8335-a5e24f6704d4 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.1 for WordPress allows remote atta… wordfence
bac57319-3b0c-4b83-af9e-7b5539ef087a
< 2.4
HIGH 8.8 The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php… wordfence
bab07bc7-d428-4ef9-91e8-4203fc8a32dd
< 1.6.6
HIGH 8.8 The RTMKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
ba79bf95-08f8-4aa6-968b-f76a09ce52b8
< 4.2.6.9
HIGH 8.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to… wordfence
ba317acb-d45c-42c0-b5fb-b163bcd59340
< 1.7.1
HIGH 8.8 The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the cntctfrmtdb_department… wordfence
ba0a1b59-90c2-4bdd-9594-5866df96cfb8 HIGH 8.8 The Wovax IDX plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… wordfence
b9f99b51-e1b1-4cd3-a9f7-24e4b59811a7
< 1.14.6
HIGH 8.8 The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 … wordfence
b9ead8f1-f2d7-4087-bb6c-de15bf8318a3
< 1.2.9
HIGH 8.8 Metronet Tag Manager version 1.2.7 contains a Cross site Request Forgery (CSRF) vulnerability in Settings page /wp-admin… wordfence
b9e499c4-e683-4587-b0ab-7f4ecde94e41
< 2.7.7
HIGH 8.8 The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
b994f9ee-b59b-4bcd-9057-4cfbb5f22694 HIGH 8.8 The Wayne Audio Player plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
b97d2b63-7eaa-4518-b838-35d4b993743d
< 1.20.1
HIGH 8.8 The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerabl… wordfence
← Prev 135 136 137 138 139 140 141 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top